diy solar

diy solar

Understanding Victron's VRM security

KevinC_63559

New Member
Joined
Jan 26, 2024
Messages
125
Location
NE Missouri, USA
This off, let me admit that I'm paranoid. Might also want to mention that served me well during my corporate and consulting life. I'm never surprised by what people try and get away with in contracts... anyhow:

I have my first Victron Multiplus II up and running, and have a cerbo-like Pi setup with VenusOS. VictronConnect works with it just fine. Actually updated the firmware on my MK3-USB complements of that system.

I'd like to get some system logging going.

VRM is the obvious default, but that paranoia gets in the way. My worst case scenario is that someone hacks Victron and gets control of my power infrastructure.

I'm presuming VRM is simply protected via a userid/password. Is it possible to set that up as a logging only site? Should I unexpectedly require support, could I toggle something to allow the likes of CurrentConnected to login and control my devices? If yes, how can I prevent that if my credentials (or the entire site) is hacked?

Thanks!
 
You can set up 2FA authentication for your VRM account. I also believe by default it is setup as a one way (log only) control.

I'm not sure if there's a way to disable the Remote Console in the VRM.

You could always look at designing your own local interface if you want.
 
Exploring Grafana now, as a backup. Bit tricker, but might work out better. Time will tell.

2FA helps keep my credentials private, but doesn't help in case of a site hack.

FYI - besides HomeDepot getting hacked a few years ago, my regional hospital has been hacked twice - exposing HIPPA data. I'm just a bit gun-shy of using anything Portal like these days.
 
You can disable two-way communication on your GX device. If I remember the location properly, it should be under menu->settings->remote console, so it only sends data to VRM but cannot receive data or commands. This would disable remote console and limit the ability of someone accessing your account from turning off your power switch.
 
Back
Top